As Healthcare Organizations Increase Vendor Scrutiny, Medcurity Launches SRA Built for Business Associates

Business professionals collaborating around a desktop computer and tablet.

Spokane, WA – August 27, 2026 – Hospitals, health centers, and health systems across the country are dramatically tightening their third-party risk requirements, forcing a fundamental shift in how healthcare vendors prove their compliance. Where a signed Business Associate Agreement once satisfied prospective clients, healthcare organizations are now actively auditing vendor security practices before signing contracts or approving renewals. In response to this rising vendor scrutiny, Medcurity today launched a Security Risk Analysis built specifically for business associates: the billing companies, technology providers, laboratories, and consultants that handle protected health information on behalf of healthcare organizations.

The shift reflects a critical reality: business associates have been directly liable under HIPAA since the HITECH Act, but covered entities are no longer taking a vendor’s word for their security posture. Today, the demand for a verified Security Risk Analysis has migrated from the health system down to every partner in its ecosystem.

A healthcare vendor doesn’t have the same risk profile as a hospital, so completing a generic provider assessment can leave gaps. Medcurity built its new analysis around the vendor’s side of that relationship: evaluating how an organization handles client data, how it supports its clients’ compliance obligations, and where subcontractor risks lie. Findings translate into prioritized improvements backed by specific HIPAA provisions, alongside required policies and custom-branded documentation built to hand directly to requesting clients.

“If you handle patient data on behalf of a healthcare organization, you carry the same obligation they do. Beyond meeting the HIPAA requirement, this is a critical exercise for understanding and reducing the risk of a data breach. I want the vendors we work with to have it handled before their clients ask,” said Joe Gellatly, CEO of Medcurity.

About Medcurity

Headquartered in Spokane, WA, Medcurity is a leading provider of healthcare compliance solutions. The company’s mission is to bring clarity and confidence to HIPAA compliance. With decades of experience in healthcare, technology, and compliance, the Medcurity team offers tools and expertise to protect patient data and guide healthcare organizations through regulatory landscapes.

Learn more about Medcurity’s HIPAA Security Risk Analysis for Business Associates:
https://medcurity.com/hipaa-compliance-solutions/business-associate-sra/

Contact

Medcurity
509-867-3645
157 S. Howard Street, Suite 603
Spokane, WA 99201